Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

IIBA-CCA Certificate in Cybersecurity Analysis (CCA) Questions and Answers

Questions 4

SSL/TLS encryption capability is provided by:

Options:

A.

certificates.

B.

protocols.

C.

passwords.

D.

controls.

Buy Now
Questions 5

Which of the following should be addressed by functional security requirements?

Options:

A.

System reliability

B.

User privileges

C.

Identified vulnerabilities

D.

Performance and stability

Buy Now
Questions 6

There are three states in which data can exist:

Options:

A.

at dead, in action, in use.

B.

at dormant, in mobile, in use.

C.

at sleep, in awake, in use.

D.

at rest, in transit, in use.

Buy Now
Questions 7

Which of the following control methods is used to protect integrity?

Options:

A.

Principle of Least Privilege

B.

Biometric Verification

C.

Anti-Malicious Code Detection

D.

Backups and Redundancy

Buy Now
Questions 8

Analyst B has discovered multiple attempts from unauthorized users to access confidential data. This is most likely?

Options:

A.

Admin

B.

Hacker

C.

User

D.

IT Support

Buy Now
Questions 9

What things must be identified to define an attack vector?

Options:

A.

The platform, application, and data

B.

The attacker and the vulnerability

C.

The system, transport protocol, and target

D.

The source, processor, and content

Buy Now
Questions 10

Other than the Requirements Analysis document, in what project deliverable should Vendor Security Requirements be included?

Options:

A.

Training Plan

B.

Business Continuity Plan

C.

Project Charter

D.

Request For Proposals

Buy Now
Questions 11

Organizations who don't quantify this will likely miss opportunities toward achieving strategic goals and objectives:

Options:

A.

cybersecurity budget.

B.

control effectiveness.

C.

risk estimation.

D.

risk appetite.

Buy Now
Questions 12

What is the "impact" in the context of cybersecurity risk?

Options:

A.

The potential for violation of privacy laws and regulations from a cybersecurity breach

B.

The financial costs to the organization resulting from a breach

C.

The probability that a breach will occur within a given period of time

D.

The magnitude of harm that can be expected from unauthorized information use

Buy Now
Questions 13

Where business process diagrams can be used to identify vulnerabilities within solution processes, what tool can be used to identify vulnerabilities within solution technology?

Options:

A.

Vulnerability-as-a-Service

B.

Penetration Test

C.

Security Patch

D.

Smoke Test

Buy Now
Questions 14

What risk factors should the analyst consider when assessing the Overall Likelihood of a threat?

Options:

A.

Attack Initiation Likelihood and Initiated Attack Success Likelihood

B.

Risk Level, Risk Impact, and Mitigation Strategy

C.

Overall Site Traffic and Commerce Volume

D.

Past Experience and Trends

Buy Now
Questions 15

NIST 800-30 defines cyber risk as a function of the likelihood of a given threat-source exercising a potential vulnerability, and:

Options:

A.

the pre-disposing conditions of the vulnerability.

B.

the probability of detecting damage to the infrastructure.

C.

the effectiveness of the control assurance framework.

D.

the resulting impact of that adverse event on the organization.

Buy Now
Questions 16

The process by which organizations assess the data they hold and the level of protection it should be given based on its risk to loss or harm from disclosure, is known as:

Options:

A.

vulnerability assessment.

B.

internal audit.

C.

information classification.

D.

information categorization.

Buy Now
Questions 17

Certificates that provide SSL/TLS encryption capability:

Options:

A.

are similar to the unencrypted data.

B.

can be purchased from certificate authorities.

C.

are for data located on thumb drives.

D.

can provide authorization of data access.

Buy Now
Questions 18

What is the definition of privileged account management?

Options:

A.

Establishing and maintaining access rights and controls for users who require elevated privileges to an entity for an administrative or support function

B.

Applying identity and access management controls

C.

Managing senior leadership and executive accounts

D.

Managing independent authentication of accounts

Buy Now
Questions 19

What is the first step of the forensic process?

Options:

A.

Reporting

B.

Examination

C.

Analysis

D.

Collection

Buy Now
Questions 20

What is an embedded system?

Options:

A.

A system that is located in a secure underground facility

B.

A system placed in a location and designed so it cannot be easily removed

C.

It provides computing services in a small form factor with limited processing power

D.

It safeguards the cryptographic infrastructure by storing keys inside a tamper-resistant external device

Buy Now
Questions 21

Which of the following activities are part of the business analyst’s role in ensuring compliance with security policies?

Options:

A.

Auditing enterprise security policies to ensure that they comply with regulations

B.

Ensuring that security policies are reflected in the solution requirements

C.

Testing applications to identify potential security holes

D.

Checking to ensure that business users follow the security requirements

Buy Now
Questions 22

Which statement is true about a data warehouse?

Options:

A.

Data stored in a data warehouse is used for analytical purposes, not operational tasks

B.

The data warehouse must use the same data structures as production systems

C.

Data warehouses should act as a central repository for the data generated by all operational systems

D.

Data cleaning must be done on operational systems before the data is transferred to a data warehouse

Buy Now
Exam Code: IIBA-CCA
Exam Name: Certificate in Cybersecurity Analysis (CCA)
Last Update: May 22, 2026
Questions: 75

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11